Ransomware victim disclosure
← All victimsHudson MD Group, LLC
Claimed by METAENCRYPTER · listed 4 hours ago
Status timeline
- ListedSep 22, 2026
Current state: Listed for ransom
At a glance
- Group
- METAENCRYPTER
- Status
- Listed for ransom
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Sep 22, 2026
- Data size
- 1 TB
About the victim
AI dossier — public-source company profileHudson MD Group, LLC is a U.S.-based multispecialty medical group headquartered in West Orange, New Jersey, established in 2019. The organization operates a network of outpatient medical practices and care centers throughout New Jersey, providing a broad range of healthcare services including primary care, cardiology, gastroenterology, neurology, obstetrics and gynecology, nephrology, urology, and other specialized medical services.
- Industry
- Healthcare Services - Multispecialty Medical Group
- Address
- West Orange, New Jersey, United States
- Founded
- 2019
Attack summary
Severity: critical — Confirmed exfiltration of 2 TB of data from a healthcare provider. Healthcare organizations handle protected health information (PHI) and personally identifiable information (PII) at scale, which is regulated under HIPAA and other privacy laws. The volume and healthcare sector classification place this in the critical category regardless of the specific data types disclosed.METAENCRYPTER claims to have exfiltrated 2 TB of internal data from Hudson MD Group, LLC. The group states that an additional 1 TB was exfiltrated within 24 hours, indicating the company remains vulnerable. The leak post does not specify a ransom demand or provide details on the data categories beyond the volume.
Data the group says was taken
AI dossier — extracted from the leak post- Internal company files
- Patient records (inferred from healthcare provider status)
- Administrative data
What the group claims
A U.S.-based multispecialty medical group headquartered in West Orange, New Jersey. Established in 2019, the organization brings together physicians and healthcare professionals across multiple medical specialties and operates a network of outpatient medical practices and care centers throughout New Jersey. Provides primary and internal medicine, cardiology, gastroenterology, neurology, obstetrics and gynecology, nephrology, urology, and other specialized medical services.
The leak post
captured from the group's siteThis platform publishes data belonging to organizations that have elected to forgo negotiation entirely.Upon a company's initial listing, the complete manifest of exfiltrated files is disclosed alongside a curated selection of representative samples. Should the organization fail to establish contact prior to the stated deadline, a portion of the compromised data is released into the public domain.Should all subsequent attempts at resolution prove fruitless, the full volume of acquired data is made permanently and unconditionally available to the general public — accessible without restriction to journalists, researchers, competitors, and any other interested party. Simultaneously, formal notifications are dispatched to the relevant data protection and regulatory authorities: the and in the United States; the , , , and the across Europe; the (Singapore), (South Korea), and (Japan) throughout Asia — all of whom are mandated to investigate and impose penalties upon the affected organization.In the event that a mutual agreement is reached, every file in our possession is permanently and irrevocably destroyed, and all references to that organization are expunged from this platform in th…
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

